---
redirect_from:
  - /cloud/access-control/
---

# Access Control

As an account administrator, you can define roles with specific permissions for
resources and apply those roles to users within the account.

<SuccessBox>

Access control is available in Cube Cloud on
[Enterprise](https://cube.dev/pricing) tier.
[Contact us](https://cube.dev/contact) for details.

</SuccessBox>

## List all roles

To see a list of roles in your account, first go to the Team settings page by
clicking on your avatar in the top right corner, then clicking on the "Team"
button.

On the Team settings page, click the "Roles" tab to see all the roles in your
account:

<Screenshot
  alt="Cube Cloud Team Roles tab"
  src="https://ucarecdn.com/476cb30f-4939-41a8-a399-53d4f8a47dee/"
/>

## Create a role

To create a new role, click the "Add Role" button. Enter a name and optional
description for the role, then click "Add Policy" and select either "Deployment"
or "Global" for this policy's scope.

Deployment policies apply to deployment-level functionality, such as the
Playground and Data Model editor. Global policies apply to account-level
functionality, such as Billing. Once the policy scope has been
selected, you can restrict which actions this role can perform by selecting
"Specific" and using the dropdown to select specific actions.

<Screenshot
  alt="Cube Cloud Team Roles tab"
  src="https://ucarecdn.com/2bbda93d-9da9-4c1e-8c7a-816a2d9ac8a9/"
/>

When you are finished, click "Create Role" to create the role.

## Assigning roles to users

Roles are assigned to new users when inviting them:

<Screenshot
  alt="Cube Cloud Team Roles tab"
  src="https://ucarecdn.com/5636a7d9-11de-45eb-aead-a23d9d780e52/"
/>

Existing users' roles can be modified from the "Members" tab on the Team page:

<Screenshot
  alt="Cube Cloud Team Roles tab"
  src="https://ucarecdn.com/a72cad30-487b-484a-b557-0f0e157c89b1/"
/>
